Privacy Policy

Last updated:

This Privacy Policy describes how Mergestorm ("we," "us," or "our") may collect, use, and share information when you use our website and application.

Information we may collect

Mergestorm is an AI code-review product for GitHub pull requests. Depending on how you use the service, we may process: account details you provide (such as name and email from GitHub or Google sign-in), GitHub repository metadata and pull request content (diffs, commits, linked issues) needed to run reviews and generate inline comments and check runs, billing and subscription data via our payment processor, usage and credit balances, and technical logs (for example IP address, device type, and approximate location) to operate and improve the service.

AI model providers

To review and fix your pull requests, we send repository content to the AI model providers below. This includes diffs, file contents, commit messages, and pull request and comment text. We use each provider's business API.

  • OpenAI (GPT-6 Luna, GPT-5.6 Luna): every Vortex review, Vortex comment triage, the Vortex summary of your repository's rules files, and Cyclone patches. GPT-5.6 Luna is the backup when GPT-6 Luna does not answer. In dashboard chat, GPT-5.6 Luna sorts each message, explains findings, summarizes long threads, and answers the signed-out demo chat.
  • DeepSeek (DeepSeek V4 Flash, DeepSeek V4 Pro): dashboard chat answers, Cyclone comment triage, the Cyclone summary of your repository's rules files, and the title of a review unit's land PR. Requests go to DeepSeek's own API. DeepSeek is based in China.
  • Anthropic (Claude Haiku 4.5): Cyclone comment triage when DeepSeek does not answer.

Surge CI runners, the merge queue, and Auto land do not send your code to an AI model provider.

Model training

Mergestorm does not train models on your code. We send code to the providers above through their business and API offerings.

How long we keep data

  • Your account, settings, reviews, findings, chats, review jobs, and history: kept until you delete your account.
  • Copies of your code on our review workers (snapshots and work folders): deleted 7 days after they were last written.
  • Cyclone checkouts of your repository: deleted 7 days after Cyclone last used them. The temporary home folder for each patch run is deleted when the run ends.
  • Model responses, which can quote your code, logged with the repository and pull request they belong to: deleted about 14 days after they are written.
  • Service logs: rotated by size. We keep the current file and five 5 MB archives per service, so older lines are deleted as new ones arrive. There is no fixed time limit.
  • Surge runner machines: the job folder is wiped after every job. Each machine is deleted when there is no work for it, and no machine lives longer than 9 hours.

Cookies and consent

We use strictly necessary cookies (such as session tokens and the last Work chat tab) to keep you signed in, restore your workspace, and protect against abuse. These do not require consent because the service cannot function without them.

Microsoft Clarity is only activated after you give consent. On other pages, a cookie banner appears on your first visit; on this page you can manage analytics cookies directly in the Cookie preferences panel below. Google Analytics (G-8CWNJ0LWWL) and Google Ads measurement use Google Consent Mode in denied-by-default mode: our layout initializes gtag('consent', 'default') with storage/personalization denied and still calls gtag('config', 'G-8CWNJ0LWWL') and gtag('config', 'AW-18229804651'), which can send limited cookieless, non-personalized measurement pings on page load. Cookie preferences on this page is where you change that choice; personalization/storage stays disabled unless you grant consent.

Third-party services

We may rely on vendors for hosting, authentication, payments, analytics, email delivery, or error reporting. For example, we may use Microsoft Clarity and Google Analytics to better understand aggregate usage and interaction patterns (such as clicks and page behavior) so we can improve product usability. Those providers process data according to their own policies and our agreements with them, only as needed to deliver the product.

Marketing email

We send marketing email, such as product news, offers, and free credits, only if you opt in. The box to opt in at sign-in is never pre-ticked. We record when you opted in, where (sign-in or Account settings), and the wording you agreed to.

You can withdraw consent at any time with the Email toggle in Account settings or the unsubscribe link in any of our emails. Withdrawing is free and takes effect for the next email we send.

Transactional and account email, such as the welcome message and subscription and billing notices, is separate. We send it to run your account whether or not you opt in to marketing email.

Account deletion

You can request irreversible account deletion from Account settings. We revoke sessions and product API keys, stop your active work, cancel subscriptions, and delete your account-owned database records, including chats, review jobs, history, settings, and session metadata. Failed steps retry automatically.

Shared repository records and other users’ installation, repository, and history records remain. Worker snapshots, checkouts, prompts, and agent homes are queued for separate cleanup; accepting an account deletion request does not mean those files are gone. This flow does not delete data already held by GitHub or other vendors.

Payment providers retain invoices and billing records required for accounting and legal obligations. We retain email suppression records to honor opt-outs and minimal deletion tracking identifiers, including worker cleanup identifiers until cleanup is acknowledged.

We keep a security audit record of administrator access, GitHub installation transfers, session and API key revocations, and account deletion requests for 400 days, including after account deletion. It holds account and object identifiers, not tokens, prompts, or code.

Contact

For privacy-related questions, contact us at contact@mergestorm.ai.

See also our Terms of Service.